# The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)

> Huntress-hosted guest article walks through the first 24 hours of a ransomware incident, citing Mandiant M-Trends 2026 (14-day median dwell time; 22-second initial-access-to-ransomware-affiliate hand-off) and the CISA/FBI Akira advisory (data theft completed in just over two hours in some cases). The CISA Akira update documents the VPN-without-MFA vector, edge and backup-software CVEs, exfiltration tooling (FileZilla, WinRAR, WinSCP, RClone, Mega, Ngrok) and credential theft (Mimikatz, LaZagne, LSASS, Kerberoasting).

- **Published:** 2026-10-03T00:00:00Z
- **Last reviewed:** 2026-10-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2852
- **ID:** TL-2026-2852
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** Akira
- **Detections:** 9 · **IOCs:** 31 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2024-40766, CVE-2023-28252, CVE-2024-37085, CVE-2023-27532, CVE-2024-40711

## Description

This item is incident-response guidance rather than a new variant disclosure, but it consolidates operator tradecraft that is corroborated by the CISA #StopRansomware Akira advisory (AA24-109A, originally published 2024-04-18 and updated 2025-11-13 with the FBI, DC3, HHS, Europol EC3 and French, German and Dutch agencies).

Initial access and speed. The CISA update names VPN services without multi-factor authentication as a primary Akira entry vector, together with password spraying (SharpDomainSpray) and brute-forcing of VPN endpoints. Edge and infrastructure CVEs used for initial access or escalation are CVE-2024-40766 (SonicWall, improper access control), CVE-2023-28252 (heap-based buffer overflow), CVE-2024-37085 (authentication bypass), CVE-2023-27532 and CVE-2024-40711 (Veeam Backup; the latter a deserialization flaw). Mandiant M-Trends 2026 reports the median time from an initial access broker foothold to hand-off to a ransomware affiliate fell to 22 seconds in 2025 (from over eight hours in 2022), while global median dwell time rose to 14 days from 11.

Credential theft and discovery. The article cites Mimikatz and LaZagne for credential dumping, LSASS memory extraction and Kerberoasting against service accounts. CISA adds SAM and NTDS dumping, NetExec (including the --dpapi option), Impacket and nltest domain-controller and trust enumeration (nltest /dclist:, nltest /DOMAIN_TRUSTS). Lateral movement and C2 tooling named by CISA includes Cobalt Strike, SystemBC, POORTRY and STONESTOP loaders, LogMeIn, OpenSSH, Cloudflared and Ngrok.

Exfiltration. Staging and compression use FileZilla, WinRAR and 7-zip; transfer uses WinSCP, RClone, FTP/SFTP and the Mega cloud storage service; Ngrok provides encrypted tunnels that bypass perimeter monitoring. CISA documents data theft completed in just over two hours from initial access in some cases. Because these are legitimate tools, the article advises hunting on outbound volume and destination (unusual volume to a consumer cloud endpoint off-hours) rather than on signatures.

Impact and backup targeting. M-Trends 2026 reports operators actively targeting backup infrastructure, identity services and virtualization management planes; volume shadow copies are frequently removed with PowerShell. CISA documents PowerShell and WMIC used to disable services, firewall modification, and encryptors: Akira/Akira_v2 (.akira, .akiranew, .aki; Rust-based), the deprecated Megazord variant (.powerranges) and a Linux/ESXi encryptor that also targets Nutanix AHV. Ransom notes are fn.txt or akira_readme.txt. CISA states Akira has claimed about $244.17 million in proceeds as of late September 2025 and primarily targets small and medium-sized businesses, with a notable preference for educational institutions.

The article also names REDBIKE and AGENDA in the context of backup-infrastructure targeting; it provides no specific IPs, hashes or hostnames. The two SHA-256 hashes below come from the CISA advisory, not the article. The article's statistics are second-hand citations; Akira details were corroborated against the CISA advisory, and M-Trends figures against the Google Cloud M-Trends 2026 coverage.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1078 Valid Accounts
- T1110.003 Password Spraying
- T1003.001 LSASS Memory
- T1003.002 Security Account Manager
- T1003.003 NTDS
- T1558.003 Kerberoasting
- T1555 Credentials from Password Stores
- T1482 Domain Trust Discovery
- T1572 Protocol Tunneling
- T1219 Remote Access Tools
- T1560.001 Archive via Utility
- T1567.002 Exfiltration to Cloud Storage
- T1048 Exfiltration Over Alternative Protocol
- T1686 Disable or Modify System Firewall
- T1059.001 PowerShell
- T1489 Service Stop
- T1490 Inhibit System Recovery

## Sources

- [The First 24 Hours: What Actually Happens When Ransomware Lands (Huntress)](https://www.huntress.com/blog/what-happens-during-a-ransomware-attack)
- [#StopRansomware: Akira Ransomware (CISA AA24-109A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a)
- [FBI IC3 CSA: Akira Ransomware update](https://www.ic3.gov/CSA/2025/251113.pdf)
- [FBI IC3 CSA: Akira Ransomware (original advisory)](https://www.ic3.gov/CSA/2024/240418.pdf)
- [M-Trends 2026: Data, Insights, and Strategies From the Frontlines (Google Cloud / Mandiant)](https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026)
- [M-Trends 2026 Report (Executive Edition)](https://cloud.google.com/security/resources/m-trends-executive-edition)
- [AttackIQ: Updated Response to CISA Advisory AA24-109A](https://www.attackiq.com/2025/11/18/updated-response-to-cisa-advisory-aa24-109a/)
- [SafeBreach: Coverage for Updated CISA AA24-109A Akira Ransomware](https://www.safebreach.com/blog/safebreach-coverage-for-updated-cisa-aa24-109a-akira-ransomware)
- [Mandiant M-Trends 2026: ransomware hand-off time of 22 seconds](https://www.decryptiondigest.com/blog/mandiant-m-trends-2026-ransomware-breakout-time-22-seconds)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2852
